Blog

ColdBox 6.8.0 Released

Luis Majano August 01, 2022

Spread the word

Luis Majano

August 01, 2022

Spread the word


Share your thoughts

 

I am incredibly excited to announce the release of ColdBox v6.8.0 and its standalone companion libraries: CacheBox, LogBox and WireBox. This update includes some important fixes and we managed to squeeze some nice improvements!

Updating ColdBox


update coldbox

# If you are using standalone libraries, then update those
update wirebox
update cachebox
update logbox

You can find our what's new document here: https://coldbox.ortusbooks.com/intro/release-history/whats-new-with-6.8.0. So let's explore the release notes.

Release Notes

ColdBox HMVC Core

Bug

  • COLDBOX-1134 Router closure responses not marshalling complex content to json
  • COLDBOX-1132 New virtual app was always starting up the virtual coldbox app instead of checking if it was running already

Improvement

  • COLDBOX-1131 Updated Missing Action Response Code to 404 instead of 405
  • COLDBOX-1127 All core async proxies should send exceptions to the error log

New Feature

  • COLDBOX-1130 New config/ColdBox.cfc global injections: webMapping, coldboxVersion
  • COLDBOX-1126 Funnel all out and err logging on a ColdBox Scheduled Task to LogBox

Task

  • COLDBOX-1135 Remove HandlerTestCase as it is no longer in usage.

Add Your Comment

Recent Entries

BoxLang 1.17 Series Part 4 : WriteDump Enhanced!

BoxLang 1.17 Series Part 4 : WriteDump Enhanced!

You call writeDump() on an ORM entity or a very rich class graph . The browser locks up. Thirty seconds later you get a page with forty thousand rows on it, you scroll for a while, you give up, and you go edit your code to dump a sub-key instead. Or worse, you crash the server.

Luis Majano
Luis Majano
September 11, 2026
BoxLang AI 3.4 Blog Series Part 4 : Locking Down Prompt Injection

BoxLang AI 3.4 Blog Series Part 4 : Locking Down Prompt Injection

LLM applications face a class of attack traditional input validation was never built for: prompt injection. An attacker embeds instructions in user input, a retrieved document, a web page your tool fetched, or an MCP result, trying to override your system prompt, exfiltrate data, or hijack a tool call. BoxLang AI 3.4.0 ships four layered, configurable defenses against exactly this, plus one more that's on unconditionally.

Luis Majano
Luis Majano
September 11, 2026